Security Advisory

CVE-2023-53914

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-12-17 22:44:49
Last updated 2026-04-07 14:07:35
Assigner VulnCheck
CVSS score 9.3
State PUBLISHED

Description

UliCMS 2023.1 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through mass assignment in the UserController. Attackers can send a crafted POST request to the admin index.php endpoint with specific parameters to generate an administrative account with full system access.